Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 25/157
7.8
CVE-2026-57245

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida

7.8
CVE-2026-57247

The application re-enters the document structure via field processing and deletes the current page, and then continues u

7.8
CVE-2026-57249

After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e

7.8
CVE-2026-57250

When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi

7.8
CVE-2026-57252

When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio

7.8
CVE-2026-57256

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi

7.8
CVE-2026-34196

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a

7.8
CVE-2026-10667

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l

7.8
CVE-2026-44800

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-49166

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49173

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49808

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an

7.8
CVE-2026-50293

Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-54112

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an

7.8
CVE-2026-54114

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-55948

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-58602

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-47290

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-47642

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50305

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50306

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50314

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50317

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems

7.8
CVE-2026-50321

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows

7.8
CVE-2026-50326

Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50329

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50331

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50353

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50425

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50427

Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50433

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50436

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50440

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service all

7.8
CVE-2026-50457

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50458

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50466

Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50467

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50476

Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50478

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50486

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50493

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50676

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.8
CVE-2026-50677

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50688

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50689

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-54125

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

7.8
CVE-2026-54131

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55018

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55032

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55128

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started